Description
WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset the password of any user, including administrator. WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files versions 3.1 - 3.1.1.4.1 are vulnerable.
Remediation
Update to plugin version 3.1.1.4.2 or latest
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2015-6832)
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-6385)
WordPress Plugin freetobook widget Unspecified Vulnerability (1.0.5)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-15929)